Invite people and manage members

Invite someone into a shared vault, check their safety number, choose their role, then remove a member or leave a vault.

On this page
Documentation sections

Giving someone access to a shared vault takes three moves. You invite the person. They accept. Then you check their key and give them access. That last check is what makes sure the vault key goes to the right person, and to nobody else.

This article follows a real example. Alex Morgan owns the vault "Lumen project" in the desktop app. She invites her client Jordan Lee, who has a free account and uses the web app. If you haven't created a vault yet, start with Shared vaults.

Before you start

  • Only the owner and the admins of a vault can invite people. In a vault that belongs to someone else's shared space, only an administrator of that space can bring in a new person.
  • The person needs a Filarr account. The free plan is enough. If they don't have one yet, they can create it after receiving your invitation, with the address you invited.
  • Each person takes a place in your shared space: up to 3 people on Solo and 6 on Pro, you included. An invitation that hasn't been answered yet takes a place too. The Manage access window shows where you stand, for example 1 of 6 people in your shared space.

Step 1: invite the person

  1. Open the vault and click Share. The Manage access window opens.

  2. Type the person's email address in the Invite field.

  3. Choose their role. Member is selected by default. The roles are explained further down.

    For someone who isn't in your shared space yet, the button becomes Invite, and a line explains what happens next: Filarr invites them to your shared space, and once they accept, you verify their key.

  4. Click Invite.

Filarr emails the invitation and confirms it. If the email doesn't arrive, pass the link on yourself: under Email not arriving? Pass the link on yourself:, click Copy the link, or QR code to show a code the person can scan. The link only works for the address you invited.

If the person is already in your shared space, for example because they are a member of another of your vaults, the button stays Give access. There is no invitation to accept: click it and they get access. If their key has changed since you last checked it, Filarr first asks you to compare their safety number, then to click Confirm & give access.

Step 2: the person accepts

Jordan receives an email. He opens the link in it, which opens the invitation in Filarr. He can also paste the invitation himself:

  1. Go to Settings → Account & Sync and click I have an invitation. On a paid plan, or once you are already in someone's shared space, New then I have an invitation code… on Home opens the same window.

  2. Paste the link from the email, or the code it contains, then click Continue.

  3. A window titled Join followed by Alex's address explains what accepting means: Alex can share encrypted vaults with Jordan, and nothing of his is shared back. Rights are then set vault by vault. Jordan clicks Accept invitation.

Filarr confirms that the invitation is accepted, and that the vaults shared with Jordan will appear on his Home.

An invitation only opens with the account of the address it was sent to. If Jordan is signed in with another account, Filarr says so and offers to change account or profile.

Step 3: check their key and give access

Back in her vault, Alex finishes the job.

  1. Click Manage, then open the Invitations tab. Under Access being prepared, Jordan's row reads Waiting for you to check their key.

  2. Click See details. The window Where does jordan.lee@example.test's access stand? lists five steps. The first three are done: invited, active in your shared space, key published. The next one needs you.

  3. Click Check their key and give access. Filarr shows Jordan's safety number: six blocks of five digits.

  4. Call Jordan, or meet him, and ask him to read his own safety number to you, block by block. He finds it in Settings → Security → Your key fingerprint. Use a channel other than Filarr: a phone call, another messaging app, or in person.

  5. If every block matches, click the button that starts with The numbers match. Filarr marks Jordan as verified on this device.

Filarr seals the vault key for Jordan and confirms that he now has access. The invitation leaves the Invitations tab.

On Jordan's side, the vault appears on Home. In the web app, reload the page if it doesn't show up. The first time he opens it, Filarr asks for his account password in Unlock shared vaults.

Roles

Each member has a role in each vault. The role decides what they can do, not what they can read: every member can read the whole vault.

RoleWhat they can do
ViewerRead and download, follow notes live. Can't change anything or comment.
MemberEverything a viewer can do, plus add, edit and comment. Can move to the trash the items they added.
AdminEverything a member can do, plus invite and remove people, change roles, change the vault's settings, renew its key and freeze it.
OwnerEverything an admin can do, plus transfer ownership, empty the trash and delete the vault.

To change someone's role, click Manage, open the Members tab and pick a new role on their row. Nothing is re-encrypted. You can't change your own role: transfer ownership or leave the vault instead.

Remove a member

  1. Click Manage, then open the Members tab.
  2. On the person's row, choose Remove. On a narrow window, it is in the menu with three dots.
  3. Read the window Remove member from vault?, then click Remove & re-key.

Filarr gives the vault a new key and seals it for the people who stay. The person you removed can no longer read anything added afterwards. What they already downloaded stays on their device: no software can take that back.

If the key of a member who stays has changed since you last checked it, Filarr asks you to verify that member before continuing.

Leave a vault

  1. On Home, right-click the vault and choose Leave vault. You can also click Manage, open the Danger tab and click Leave vault.
  2. Confirm.

The vault stays for the other members. To come back, you need a new invitation. If you are the last owner, give ownership to someone first: see Manage a vault.

Follow or cancel an invitation

The Invitations tab of the Manage page shows where each person stands, under Access being prepared. Send the space invitation again sends the invitation once more, and Call off the promised access cancels it. An invitation to your shared space is valid for 7 days, and Filarr sends no automatic reminder for it. See Manage a vault.